From Wi-Fi hack to CISO: Corelight’s Bernard Brantley

From Wi-Fi hack to CISO: Corelight’s Bernard Brantley

Corelight’s first CISO on hacking his way into security, why AI hasn’t rewritten attacker tradecraft and why defenders should point AI at the basics first

Nicole Deslandes

August 6, 2026    7 Minutes Read


Sometimes realizing where your career should head comes completely out of the blue. For Bernard Brantley, CISO at San Francisco–based network security firm Corelight, it arrived when he needed Wi-Fi — and the only way to get it was hacking into a network.

That break-in helped burnish the lesson that still shapes how he runs security today: read, apply, test, verify.

Brantley took the long way into the industry, with stints at the United States Military Academy and in retail, loan origination and construction before entering tech as a data center technician. He went on to secure Microsoft’s high-value asset environments, including Xbox Live, and to build out the purple team for Amazon’s consumer payments organization.

Then Corelight came calling in 2021: “We’re looking for our first CISO — would you be interested in applying?”

Over a coffee with TechInformed, Brantley discusses that Wi-Fi lightbulb moment, and his thoughts on AI and how it’s changing the cybersecurity landscape.

When you realized you could hack into that Wi-Fi, did it feel like you’d just unlocked something in your brain, or did you always know you were technical?

I was always super inquisitive; as a kid, I would figure out what else I could learn. For the first time, in cracking that network, that was the applied inquisition that was more than just reading something out of a text. It was this constant process of learning and discovery, which I think was the bigger unlock for me.

In military academies, they base their educational programs on something called the case method. You’re given the context and resources for what you are going to discuss tomorrow, and you’re expected to show up prepared to have a discussion, not prepared to be taught. That process persisted into how I was learning and applying cybersecurity.

How does that experience of hacking inform your view of bad actors now?

I’m really intrigued by bad actors. Both of my parents were Detroit police officers. My dad was a homicide detective; my mom ran the police academy. I was always around law enforcement.

Criminals are very good at understanding an opportunity for themselves, figuring out a path to exploiting that opportunity for gain, and then ensuring that their operating model and operational security allow them to continue doing those things. The refinement of tradecraft and methodology they undertake to go execute is similar to what we’re doing on the other side — except we don’t have that thing over our back where, if we fail, we go to jail.

I don’t see it as good versus evil. It’s a refinement and honing of craft to ultimately see who’s got the better approach to solving the problem in front of us.

How has AI changed cybersecurity?

What’s the same, for me, is I still have a set of systems, a set of data that’s relevant and a goal that I need to accomplish. What’s different is that I now have access to a set of systems that lets me do things that were previously impossible, on both a small and large scale.

Throughout my career, I’ve had this dream of what would happen if I could create a “Google” for security — essentially, all the knowledge I have about threat actors, or about my environment and capabilities, my head constantly going through “what if this, what if that” — and being able to go ask those questions.

Twenty-four months ago, that would mean finding a book on the subject, finding the reference to what I wanted, then reconciling the difference between what I believed and what the text gave me, then finding an opportunity to test it. AI now gives me the ability to execute that within minutes, if not seconds.

Also, a member of my team found a 20x acceleration in the security operations domain — primarily incident triage and detection engineering — through the use of GPT-5.5. The methodology was the same, the tradecraft was the same. Being able to leverage AI to execute on that methodology and tradecraft in a more deterministic way, at the speed of compute cycles, without having to build all the underlying code ourselves, resulted in a 20x increase.

On the other side, what’s scary is that there are systems that can think faster than I can act, and there’s a whole range of knowledge that I may not have, that is now in the hands of potential adversaries or competitors. That’s very scary, both on the business side and the security side.

Are you seeing, as a result, any trends from bad actors jumping on the new opportunities AI may provide?

There’s what’s out in the public domain — there was a post by Anthropic, about [seven] months before Claude Mythos, describing how an adversary used Claude to execute an attack by stitching together multiple different prompts, asking for a bit of information here, a bit there, to break through the guardrails.

Semi-novel, but how many adversaries are actively doing that? My guess would be the top 5%. What are the rest of the adversaries doing with AI? “Hey, write a script for me so I can execute this thing I was already going to execute, at scale.”

Why would an adversary spend the money on compute and burn a zero-day exploit just to install a Bitcoin miner, which is most of what we see? I don’t see that cost-exchange ratio matching up.

For the most part, you should expect to see folks with a bit less skill able to address a larger scale of targets with low- to medium-severity attacks. At the top end, we’re in the exact same place we were: the adversary wanted a way in, they were going to find a way in. They might move a bit faster, but they haven’t explicitly changed their tradecraft.

Do you think they’re making it smarter as well? More convincing in some places?

I’d argue with phishing, we were on a path where that was happening anyway — phishing was continuing to get better. For the most part, phishing at scale is done to steal credentials, for business email compromise, for these more financially motivated attacks. The spear-phishing — the targeted means of entry for nation-states or motivated adversaries to get a foothold — that was already good, and it’s getting a little bit better.

I have personally executed red team assessments that phished people who were hard to phish, without the use of AI, because we were able to write a convincing email. Is my ability to write a 20% better email to phish those exact same people changing the way I get into an organization? Maybe at the edges, but the risk is still the same, and the basic practices of how you’re segmenting your network between the front door of your environment (your email) and the crown jewels is more important than ever, but we’re still facing the same problems.

What would your advice be to businesses today on cybersecurity threats facing them?

My advice would be: defenders, figure out how to leverage AI to accelerate the basic hygiene things we’ve either put to the side or haven’t been able to execute at scale over the last half-decade. How can you use AI to get MFA implemented across the board? How can you leverage AI to update your own phishing training and security awareness training exercises? Those very basic, fundamental things we’re just not good at, at scale — that’s the first place I would apply AI to, because we’ve got quite a bit of time before the industry reaches an equilibrium on how we use these things efficiently across the remainder of security operations, practices and controls.

So don’t feel like you’re behind because you haven’t built a fully automated AI SOC. Don’t feel like you’re behind because you don’t have a fully scaled, AI-automated vulnerability assessment pipeline — those things will get to an answer soon enough. But do feel like you’re behind if you’re not actively trying to solve the basic hygiene problems using AI within your own ecosystems.

How do you have your coffee?

I’ve been drinking Americanos in a rush, but if I’m out, I usually do a dirty chai latte.

10 Leaders Defining the Future of Tech

Discover who’s setting the agenda for 2025.

VIEW LEADERS

10 Leaders Defining the Future of Tech

Discover who’s setting the agenda for 2025.

VIEW LEADERS